Welcome Guest [Log In] [Register]
We hope you enjoy your visit. You're currently viewing our forum as a guest. This means you are limited to certain areas of the board, ads are displayed, and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free.

Join our community!

If you're already a member please log in to your account to access all of our features:

Username:   Password:
Add Reply
Adobe Updates
Topic Started: Thursday, 25. October 2007, 06:29 (187 Views)
msequine
Member Avatar
Originator

Adobe Updates for Microsoft Windows Vulnerability

Systems Affected:
Microsoft Windows XP (Vista users are not affected) and Windows Server 2003 systems with Internet Explorer 7 and any of the following Adobe products:

  • Adobe Reader 8.1 and earlier
  • Adobe Acrobat Professional, 3D, and Standard 8.1 and earlier
  • Adobe Reader 7.0.9 and earlier
  • Adobe Acrobat Professional, 3D, Standard, and Elements 7.0.9 and earlier
Overview
Microsoft Windows XP and Server 2003 systems with Internet Explorer 7 contain a vulnerability that could allow an attacker to take control of your computer by convincing you to open a malicious PDF document. Public reports indicate that this vulnerability is being actively exploited.

Solution Apply an update
Adobe has released Adobe Reader 8.1.1 and Adobe Acrobat 8.1.1 to address this issue. Please see Adobe Security Bulletin APSB07-18 for details.
Posted Image

Posted Image

"Use what talents you possess; the woods would be very silent if no birds sang there except those that sang best." - Henry Van Dyke
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Original release date: February 12, 2008

Systems Affected
===Adobe Reader 8.1.1 and earlier
===Adobe Acrobat Professional, 3D, and Standard 8.1.1 and earlier

Overview Adobe Reader and Adobe Acrobat are affected by multiple vulnerabilities. At least one of these vulnerabilities is being actively exploited. The SANS Internet Storm Center Handler's Diary contains more information.Adobe has released Security advisory APSA08-01 to address these vulnerabilities, the most serious of which may allow a remote attacker to take control of your computer.

Solution Upgrade. Upgrade to Adobe Reader and Adobe Acrobat 8.1.2 as described in Adobe Security advisory APSA08-01. http://www.adobe.com/support/security/advi.../apsa08-01.html
Posted Image

Posted Image

"Use what talents you possess; the woods would be very silent if no birds sang there except those that sang best." - Henry Van Dyke
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Adobe Reader and Acrobat Vulnerabilities
Original release date: November 04, 2008

Systems Affected


  • Adobe Reader version 8.1.2 and earlier
  • Adobe Acrobat (Professional, 3D, and Standard) version 8.1.2 and earlier

    Overview: By convincing a user to download a malicious PDF file, an attacker could execute code or cause a computer to crash. The malicious file could be downloaded by just visiting a malicious website that contains the file.

    Solution
    1. Upgrade: Adobe recommends that users with version 8 of Adobe Reader or Acrobat upgrade to version 8.1.3. Links to these versions are available in the security bulletin at:
    http://www.adobe.com/support/security/bulletins/apsb08-19.html

    2. Disable JavaScript in Adobe Reader and Acrobat: Disabling JavaScript in Adobe Reader and Acrobat may prevent this vulnerability from being exploited. In Acrobat Reader, JavaScript can be disabled in the General preferences dialog:

    • Open the Edit menu
    • Choose the Preferences option
    • Choose the JavaScript option
    • De-select "Enable Acrobat JavaScript"
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Adobe Acrobat and Reader Vulnerability

In Security Bulletin APSB09-01, Adobe describes an issue that affects some versions of Adobe Reader and Acrobat. If a user visits a web site and opens a malicious PDF file in the browser, an attacker could execute code or cause a computer to crash. Note: Web browsers may be configured to open PDF files automatically.

Solution:
Disable JavaScript in Adobe Reader and Acrobat Disabling Javascript may prevent exploitation of this vulnerability. Acrobat JavaScript can be disabled using the Preferences menu (Edit -> Preferences -> JavaScript and un-check Enable Acrobat JavaScript).

Disable the display of PDF documents in the web browser Preventing PDF documents from opening inside a web browser will help mitigate this vulnerability. To prevent PDF documents from automatically being opened in a web browser, do the following:

1. Open Adobe Acrobat Reader.
2. Open the Edit menu.
3. Choose the preferences option.
4. Choose the Internet section.
5. Un-check the "Display PDF in browser" check box.

Do not open unfamiliar or unexpected PDF documents, particularly those hosted on web sites or delivered as email attachments.
Offline Profile Quote Post Goto Top
 
WldHrtRnch
Member Avatar
Wild At Heart

No patch for a fix?? Spybot found a registry change (key deleted) when I tried the above???? Weird.
Posted Image
"If you're not living on the edge, you're taking up too much space"
“And in the end, it's not the years in your life that count. It's the life in your years.” ~Abraham Lincoln
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Not yet; according to the bulletin, they'll be releasing a fix next month.

The registry is composed of various software's work processes on your computer. When you changed one of the processes, in this case disabling the JavaScript, Spybot/TeaTimer notified you of the change -- a good thing!
Offline Profile Quote Post Goto Top
 
WldHrtRnch
Member Avatar
Wild At Heart

:thanks:
Posted Image
"If you're not living on the edge, you're taking up too much space"
“And in the end, it's not the years in your life that count. It's the life in your years.” ~Abraham Lincoln
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Adobe categorizes this update as critical
Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader 9.1 and Acrobat 9.1.

Adobe recommends users of Acrobat 8 update to Acrobat 8.1.4,
and users of Acrobat 7 update to Acrobat 7.1.1.

For Adobe Reader users who can't update to Adobe Reader 9.1, Adobe has provided the Adobe Reader 8.1.4 and Adobe Reader 7.1.1 updates.

These updates resolve the issue from Security Advisory APSA09-01 and Security Bulletin APSB09-03.

Users who have previously updated to Adobe Reader 9.1 and Acrobat 9.1 for Windows and Macintosh need not take any action.

Adobe plans to make available Adobe Reader 9.1 and Adobe Reader 8.1.4 for Unix by March 25.

For more info and download updates, please go to:

http://www.adobe.com/support/security/bulletins/apsb09-04.html
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

http://www.heise.de/english/newsticker/news/print/136628

F-Secure is advising NOT to use Adobe Reader due to the many flaws that allow criminals to attack the user's computer.
Quote:
 
Of the targeted attacks on managers, politicians and other high-ranking individuals registered this year, almost 50 per cent have exploited six security vulnerabilities in Adobe's PDF products.
Quote:
 
The attacks involve criminals sending prepared documents to their victims in order to infect and spy on their PCs.
Quote:
 
According to Hypponen, users often fail to update their applications and are not aware that important security updates have been released. Automatic update requests were also often ignored. In Hypponen's opinion, Adobe should establish a regular update cycle for its products in the same way as Microsoft.

If you need a substitute for Adobe Reader, try Foxit Reader, found here:
http://www.foxitsoftware.com/pdf/reader/download.php

In addition to the interactive form filler, it includes such features as:
Quote:
 
Annotation tool: Have you ever wished to annotate (or comment on) a PDF document when you are reading it? Foxit Reader allows you to draw graphics, highlight text, type text and make notes on a PDF document and then print out or save the annotated document.
Text converter: You may convert the whole PDF document into a simple text file.
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

http://www.computerworld.com/action/article.do?command=printArticleBasic&taxonomyName=Security&articleId=9132307&taxonomyId=17

Adobe confirms PDF zero-day, urges users to kill JavaScript
Quote:
 
April 29, 2009 (Computerworld) Adobe Systems Inc. late yesterday acknowledged that all versions of its popular PDF software, including editions for Windows, the Mac and Linux, contain at least one, and possibly two, critical vulnerabilities.

"All currently supported shipping versions of Adobe Reader and Acrobat, [Versions] 9.1, 8.1.4 and 7.1.1 and earlier, are vulnerable to this issue," said David Lenoe, the company's security program manager, in a blog entry yesterday.
Quote:
 
In lieu of a patch, Lenoe recommended that users disable JavaScript in Reader and Acrobat by selecting Preferences from the Edit menu, choosing "JavaScript," then unchecking the "Enable Acrobat JavaScript" option. (On the Mac, Preferences is under the "Adobe Reader" or "Adobe Acrobat" menus.)
Quote:
 
If Adobe's patching pace for the newest bugs matches that of the February incident, it should have a fix available during the week of May 18.

Andrew Storms, director of security operations at nCircle Network Security Inc., who yesterday blasted Adobe for its long-running "rash" of JavaScript vulnerabilities, today applauded the company for reacting faster -- even as he again criticized its buggy software.

"Getting mitigations and work-around information out in front of the people in the security trenches is key," Storms said in an instant message. "Unfortunately, for Adobe, disabling JavaScript is a broken record, [and] similar to what we've seen in the past with Microsoft on ActiveX bugs."

Some security experts have urged users to switch PDF viewers. Finnish security company F-Secure Corp. repeated that recommendation today. "We've said it before, but it's worth repeating -- use an alternative to Adobe Acrobat Reader," said Patrik Runald, a security response manager at F-Secure, in a notice on the company's site. "[And] if you can't change from Adobe Reader, we strongly recommend that you disable its ability to run JavaScript."


If you need/want an alternative to Adobe Reader, see the post directly above this one.
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Adobe Security Bulletin:
- Security Updates available for Adobe Reader and Acrobat
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

APSB09-06 - Security Updates available for Adobe Reader and Acrobat

Originally posted: May 12, 2009

Summary:
A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493).

Adobe recommends users of Adobe Reader 9.1 and Acrobat 9.1 and earlier versions update to Adobe Reader 9.1.1 and Acrobat 9.1.1. Adobe recommends users of Acrobat 8 update to Acrobat 8.1.5, and users of Acrobat 7 update to Acrobat 7.1.2. For Adobe Reader users who can't update to Adobe Reader 9.1.1, Adobe has provided the Adobe Reader 8.1.5 and Adobe Reader 7.1.2 updates.


Learn more: http://direct.adobe.com/r?xllJlJqETHHqEJqJTWnJv

Severity Rating:
Adobe categorizes this update as critical:
http://direct.adobe.com/r?xllJlJqETHHvEJqJTWnJn
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
APSB09-07 - Security Updates available for Adobe Reader and Acrobat
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Summary:
Critical vulnerabilities have been identified in Adobe Reader 9.1.1 and Acrobat 9.1.1 and earlier versions. These vulnerabilities would cause the application to crash and could potentially allow an attacker to take control of the affected
system.

Adobe recommends users of Adobe Reader 9 and Acrobat 9 and earlier versions update to Adobe Reader 9.1.2 and Acrobat 9.1.2. Adobe recommends users of Acrobat 8 update to Acrobat 8.1.6, and users of Acrobat 7 update to Acrobat 7.1.3. For Adobe Reader users who can't update to Adobe Reader 9.1.2, Adobe has provided the Adobe Reader 8.1.6 and Adobe Reader 7.1.3 updates. Updates apply to Windows and Macintosh. Security updates for Adobe Reader on the UNIX platform will be available on June 16, 2009; the Bulletin will be updated to reflect their availability on that date.

This update incorporates the initial output of code hardening efforts discussed in a May 20 Adobe ASSET (Adobe Secure Software Engineering Team) blog post, as well as externally reported issues.

Learn more:
http://direct.adobe.com/r?xlPJnqTETcHqEJqJTWnln

Severity Rating:
Adobe categorizes this update as critical:
http://direct.adobe.com/r?xlPJnqTETcHWEJqJTWnlP
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

APSB09-08 - Security Update available for Shockwave Player

Originally posted: June 23, 2009

Summary:
A critical vulnerability has been identified in Adobe Shockwave Player 11.5.0.596 and earlier versions. This vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Adobe has provided a solution for the reported vulnerability. It is recommended that users update their installations using the instructions provided.


Learn more:
http://direct.adobe.com/r?xlPvqvnETJWqEJqJTWnnH

Severity Rating:
Adobe categorizes this update as critical:
http://direct.adobe.com/r?xlPvqvnETJWvEJqJTWnPW
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Adobe Security Bulletin:
- Security Updates available for Adobe Reader and Acrobat

Severity Rating:
Adobe categorizes these updates as critical:


Critical vulnerabilities have been identified in Adobe Reader 9.1.3 and Acrobat 9.1.3, Adobe Reader 8.1.6 and Acrobat 8.1.6 for Windows, Macintosh and UNIX, and Adobe Reader 7.1.3 and Acrobat 7.1.3 for Windows and Macintosh. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. This update represents the second quarterly security update for Adobe Reader and Acrobat.

Adobe recommends users of Adobe Reader 9.1.3 and Acrobat 9.1.3 and earlier versions update to Adobe Reader 9.2 and Acrobat 9.2. Adobe recommends users of Acrobat 8.1.6 and earlier versions update to Acrobat 8.1.7, and users of Acrobat 7.1.3 and earlier versions update to Acrobat 7.1.4. For Adobe Reader users who cannot update to Adobe Reader 9.2, Adobe has provided the Adobe Reader 8.1.7 and Adobe Reader 7.1.4 updates.

Updates apply to all platforms: Windows, Macintosh and UNIX.

Learn more:
http://www.adobe.com/support/security/bulletins/apsb09-15.html

Adobe Reader users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows

Adobe Reader users on Macintosh can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh

Adobe Reader users on UNIX can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix
Offline Profile Quote Post Goto Top
 
msequine
Member Avatar
Originator

Adobe Flash Flaw Frighteningly Bad!
Quote:
 
Hackers can exploit a flaw in Adobe's Flash to compromise nearly every Web site that allows users to upload content, including Google's Gmail, then launch silent attacks on visitors to those sites, security researchers said today.

Adobe did not dispute the researchers' claims, but said that Web designers and administrators have a responsibility to craft their applications and sites to prevent such attacks.

"The magnitude of this is huge," said Mike Murray, the chief information security officer at Orlando, Fla.-based Foreground Security. "Any site that allows user-uploadable content is vulnerable, and most are not configured to prevent this."
Quote:
 
The only current defense users can employ against such attacks is to stop using Flash, or failing that, restrict its use to sites known to be safe with tools such as the NoScript add-on for Mozilla's Firefox, or ToggleFlash for Microsoft's Internet Explorer.

"The best mitigation is to not use Flash," argued Murray, "but we know that that's impossible for most users, since Flash is so widely used on the Web."

"Almost everyone using the Internet is vulnerable to a Web site that allows content to be updated inappropriately," said Murray. "That's not hyperbole, it's just fact. This has the potential to affect any social media site, any career site, any dating site, many retail sites and many cloud applications. That's why this attack is so serious. End users would never know they got exploited."
Offline Profile Quote Post Goto Top
 
« Previous Topic · Computer Corner · Next Topic »
Add Reply

Use OpenDNS